Latest CVE Feed
-
5.0
MEDIUMCVE-2025-6706
An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down a server. The crash is triggered on affected versions by issuing an aggrega... Read more
Affected Products : mongodb- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
5.1
MEDIUMCVE-2025-6695
A vulnerability was found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This issue affects some unknown processing of the file /html/matPat/adicionar_categoria.php of the component Additional Categoria. The manipulation of the argument Ins... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.1
MEDIUMCVE-2025-6694
A vulnerability has been found in LabRedesCefetRJ WeGIA 3.4.0 and classified as problematic. This vulnerability affects unknown code of the file /html/matPat/adicionar_unidade.php of the component Adicionar Unidade. The manipulation of the argument Insira... Read more
Affected Products : wegia- Published: Jun. 26, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6677
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Paragraphs table allows Cross-Site Scripting (XSS).This issue affects Paragraphs table: from 2.0.0 before 2.0.5.... Read more
Affected Products : paragraphs_table- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
5.4
MEDIUMCVE-2025-6676
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Simple XML sitemap allows Cross-Site Scripting (XSS).This issue affects Simple XML sitemap: from 0.0.0 before 4.2.2.... Read more
Affected Products : simple_xml_sitemap- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-6675
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Enterprise MFA - TFA for Drupal allows Authentication Bypass.This issue affects Enterprise MFA - TFA for Drupal: from 0.0.0 before 4.8.0, from 5.2.0 before 5.2.1, from 0.0.0 ... Read more
Affected Products : miniorange_2fa- Published: Jun. 26, 2025
- Modified: Jul. 14, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2025-6674
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor5 Youtube allows Cross-Site Scripting (XSS).This issue affects CKEditor5 Youtube: from 0.0.0 before 1.0.3.... Read more
- Published: Jun. 26, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-5682
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Klaro Cookie & Consent Management allows Cross-Site Scripting (XSS).This issue affects Klaro Cookie & Consent Management: from 0.0.0 before 3.0.7.... Read more
Affected Products : klaro_cookie_\&_consent_management- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.0
MEDIUMCVE-2025-52573
iOS Simulator MCP Server (ios-simulator-mcp) is a Model Context Protocol (MCP) server for interacting with iOS simulators. Versions prior to 1.3.3 are written in a way that is vulnerable to command injection vulnerability attacks as part of some of its MC... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-49003
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" become... Read more
Affected Products : dataease- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-48923
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Toc.Js allows Cross-Site Scripting (XSS).This issue affects Toc.Js: from 0.0.0 before 3.2.1.... Read more
Affected Products : toc.js- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-48922
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GLightbox allows Cross-Site Scripting (XSS).This issue affects GLightbox: from 0.0.0 before 1.0.16.... Read more
Affected Products : glightbox- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Scripting
-
8.8
HIGHCVE-2025-48921
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Open Social allows Cross Site Request Forgery.This issue affects Open Social: from 0.0.0 before 12.3.14, from 12.4.0 before 12.4.13.... Read more
Affected Products : open_social- Published: Jun. 26, 2025
- Modified: Jul. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
8.5
HIGHCVE-2025-6693
A vulnerability, which was classified as critical, was found in RT-Thread up to 5.1.0. This affects the function sys_device_open/sys_device_read/sys_device_control/sys_device_init/sys_device_close/sys_device_write of the file components/drivers/core/devic... Read more
Affected Products : rt-thread- Published: Jun. 26, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
8.8
HIGHCVE-2025-6562
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary OS commands and execute them on the device.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2025-5966
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Attachments by filename keyword report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2025-5366
Zohocorp ManageEngine Exchange reporter Plus version 5722 and below are vulnerable to Stored XSS in the Folder-wise read mails with subject report.... Read more
Affected Products : manageengine_exchange_reporter_plus- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6561
Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to directly access a system configuration file and obtain plaintext administrator c... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
0.0
NONECVE-2025-3773
A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior allows an authenticated non-admin local user to extract sensitive information stored in a registry backup folder.... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Information Disclosure
-
7.2
HIGHCVE-2025-3771
A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authenticated non-admin local user to overwrite system files with SIR backup files, which can potentially cause a system crash. This was achieved by adding a mali... Read more
Affected Products :- Published: Jun. 26, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Path Traversal